Caveat: I know enough about encryption to never roll my own.
826 karma · joined July 3, 2015
Caveat: I know enough about encryption to never roll my own.
Evil things like making better weapons for people who kill innocent civilians.
Here's a couple more of his videos:
And really, I've done all I can do. I've talked it up, given powerpoint presentations, and emailed a comprehensive report about penalties for failing to comply as well as a project outline for becoming compliant.
In my limited view, this is pretty much the case. When I was telling our management team about the GDPR and how it relates to our new European-focused project, the first thing the CEO said was "how do we get around this?"
Management decided we're not gonna comply with the GDPR and just hope nobody notices.
IME, there's also a significant overlap between the execs that insist "2 years isn't enough time to get compliant" and execs that ignored it for the last 2 years. Not sure what that means, but it's at the point where I write off timeline complaints as whining and lack of forethought.
Frankly, I don't know why his wife puts up with him.
They were recorded having sex via hidden camera, without their knowledge or consent. That's a sex crime that they treated like it was leaked nude selfies.
IMO, the best solution is per-row encryption with the keys stored in a second database. This second database can still be backed up, with backups that have a maximum lifespan, eg: 30 days. When a user deletes their account, their decryption key is deleted, and is unrecoverable after the backup max life.
http://projects.thestar.com/temp-employment-agencies/
I completely agree with you. Shit security should cost money. I just think it has to be something like data leak liability insurance. The costs of having shitty security would be reflected in higher insurance premiums. That way, financial math would be firmly on the side of keeping data secure, instead of limiting exposure via corporate shell games.
Hell, this is exactly how the Tale of Two Wastelands mod gets the Fallout 3 content into New Vegas. It's not a seamless process, but it's really good. I have to admit, I'm quite saddened by this turn of events.
Mostly, I wonder how different the world would be if there was an incentive to build things that don't break.
The first went through the stages of grief, and "acceptance" meant shutting down. The second company had the option to pivot and focus on a specific feature that AWS lacked, but the company decided against that plan. According to my friend over there, management is still in denial over the severity of the threat. He's looking for other work, and so are most of his co-workers.
Unfortunately, this is not good news. On the plus side, you're cognisant of what you're facing, which means you can start looking for ways to pivot. Failing that, you can decide to bail before things become critical.
I'm really sorry to hear you're in this situation. For what it's worth, you're in good company.
IME, there are far too many "senior" devs (who absolutely should know better) who never worked on any testing-heavy teams that just don't see the point. After all, there's QA, and it's not like THIS code should break THAT code in a seemingly-unrelated part of the codebase...
It's no surprise that many of them simply can't do it, and thus turn to a VERY thriving black market.
The DEA gets involved again, and now those people hooked on pain meds given to them by their doctor are in the legal cross-hairs because they're buying the same shit from somebody who illegally imported it from Mexico or China.
This is not a new problem in America. It's been an issue in the past. First it was morphine after the civil war, then it was Bayer-brand Heroin (which was marketed as a non-addictive morphine substitute) after WW1. Every time somebody gets the bright idea to restrict an opioid because of how many addicts it creates, they never seem to have an answer to the follow-up question - what do we do with the addicts? Then we are collectively shocked about the size of the black market afterwards.
Sadly, it is the other way around. Purdue spent millions of dollars advertising Oxycontin as a safe, less-addictive painkiller for chronic pain. Doctors were inundated with "FDA-approved" marketing info, telling them that this specific kind of heroin was an easy, twice-per-day way to deal with back problems, knee pain, arthritis, etc. It was so deceptive that three of their executives were found guilty of criminal charges, and the company was hit with a fine so high it was a record in the pharmaceutical industry.
After people had been prescribed what is effectively heroin on a regular basis for months or years, they were addicted.
The EFF disagrees. You can read their reasoning in the linked article.
A lot of the advice I've seen here relies on the rest of the team wanting things to get better. That's not always the case. Many teams are very proud of their unmaintanable, untestable spaghetti. Some see it as a of badge of honour that nobody else can figure out something as basic as where model validation happens (in that specific case, they marshalled all their model validation into the controller parent class, and things got worse from there).
So the first thing you need to do is figure out how open they are to changing. If they're happy with what they've got, and they don't want to change how they write code, then there's not much you can do. Cleaning as you go is a great idea. But even if there's only one other person on the team and and they don't want to change anything, they'll be generating mess twice as fast as you can clean (making a mess is always faster than cleaning).
That's my advice. Try to probe if they're willing to admit they even have a problem. Start with floating the idea of writing tests, or implementing a style guide. If they don't even want to do that, there's no way you're gonna get anything bigger out of them. At that point, you gotta decide if this job is right for you.
This is an excellent way to illustrate so many problems of this nature. "If X is a real concern, why hasn't it happened to us yet?" is such a huge problem in so many organisations, and it's so frustrating.